Impact
The vulnerability resides in the core component of Oracle Coherence, part of Oracle Fusion Middleware. An unauthenticated attacker with network access to the HTTP interface can trigger the flaw, resulting in read access to a subset of data that the application holds. This impacts the confidentiality of stored information while leaving integrity and availability untouched. The weakness corresponds to improper access control and information exposure of data resources.
Affected Systems
Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 are affected. The vulnerability is present in the core component of the Oracle Fusion Middleware stack.
Risk and Exploitability
The CVSS base score of 5.3 indicates a moderate risk, limited to confidentiality impact. The EPSS score of less than 1% suggests a low probability of real-world exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. The attack vector is an unauthenticated HTTP request to the Coherence service, requiring no additional credentials.
OpenCVE Enrichment